It's an Amazon Linux AMI with the AWS CLI pre-installed on it. It uses the AWS CLI to fetch the key from AWS SSM Parameter Store. It's granted read access to that SSM Parameter via the instance role.
The key seems to be placed in the expected location
I can't think of any changes we might have made on our side to cause that 🤔